Home Services Publications News About us Contact Recruitment Site map

May, 2008

April, 2008

March, 2008

February, 2008

January, 2008

December, 2007


News archives

News
April 24, 2008
MWR InfoSecurity publish National Rail Windows Gadget Advisory


A vulnerability was identified in the National Rail Live Departure Board gadget which rendered it vulnerable to a script injection attack that could potentially allow remote attackers to execute commands on the target system. An attacker successfully exploiting this vulnerability could execute arbitrary commands in the context of the current logged in user.

The Windows Vista operating system includes the “Windows Sidebar”. This feature allows users to display ‘gadgets’ on the Sidebar and on the Windows desktop. Gadgets are small applications which can be very flexible in design and function. They are managed by the Windows Sidebar and can be used for many purposes. The range of their functionality and sophistication is dependent upon the developer’s creativity and skill. Windows Vista includes various gadgets by default, such as a calendar, calculator, currency converter, etc.

The vendor has addressed this vulnerability and implemented a fix in version 1.1. This version is yet to be tested.
The upgrade can be found here.
The full advisory can be viewed here.
On Top
Penetration testing
Application Security Testing
Wireless Testing
Fasthold Vulnerability Assessment
Load Testing
Security Management Consultancy
Firewall Testing
Internal Penetration Testing
Physical Testing

 

home       services       news       about us       contact       recruitment       sitemap

MWR InfoSecurity St Clement House Alencon Link Basingstoke Hants RG21 7SB
Tel: 01256 300920   Fax: 01256 844083